CCPA and Email Extraction: What California's Privacy Law Means for Your Lists
On this page
What the CCPA Covers
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives California residents specific rights over their personal information. Email addresses are personal information under the law.
The CCPA applies to for-profit businesses that meet at least one of these thresholds:
- Annual gross revenue above the applicable, inflation-adjusted statutory threshold. Check the current threshold in the California Attorney General guidance.
- Buy, sell or share the personal information of 100,000 or more California consumers or households per year.
- Derive 50 percent or more of annual revenue from selling or sharing consumers' personal information.
Nonprofits and government agencies are generally exempt. Small businesses that fall below all three thresholds are also exempt, though they may still be subject to other privacy laws.
If you are not sure whether the CCPA applies to you, consult a legal professional. This guide covers the law's general requirements as they relate to email extraction, not legal advice for your specific situation.
How It Relates to Email Extraction
Extracting email addresses from files is a data processing step. The CCPA does not prohibit extraction itself, but it does regulate what you do with the personal information you collect, how you store it and what rights you must honour when a California resident makes a request.
If you extract email addresses and use them for marketing, sales or any other purpose involving California residents, assess whether your business is covered before applying the CCPA requirements to those addresses.
Collection and purpose limitation
Under the CCPA, businesses must disclose the categories of personal information they collect and the purposes for which that information is used. If you extract email addresses from documents and add them to a marketing list, that collection and its purpose should be reflected in your privacy policy.
The law also requires that you collect personal information only for disclosed purposes and not use it in ways that are incompatible with those purposes without providing additional notice.
The right to know
California residents have the right to request that a business disclose what personal information it has collected about them, the sources of that information, the purposes for collection and the categories of third parties the information has been shared with.
If you extract a California resident's email address from a document and they submit a request, you must be able to tell them that you have their address, where you obtained it and what you are doing with it. This is one reason why downloading results from Email Extractor as CSV with sources can be useful. The source column records which file each address came from, giving you a record of provenance.
The right to delete
California residents can request that a business delete their personal information. If a California resident asks you to delete their email address from your records, you must comply unless an exception applies (such as completing a transaction or complying with a legal obligation).
Maintaining a suppression list helps here. When someone requests deletion, you remove their address from active lists and add it to a suppression list so it is not re-added in future extractions.
The right to opt out of sale or sharing
If you sell or share personal information (as the CCPA defines those terms), California residents have the right to opt out. The CCPA defines "sharing" broadly to include providing personal information to a third party for cross-context behavioural advertising.
The right to correct
California residents can request that a business correct inaccurate personal information. For email addresses, this is straightforward: if the address on file is wrong, update it.
Practical Steps for Compliance
Know where your addresses come from
When you extract email addresses from files, keep a record of the source. Downloading results as CSV with sources in Email Extractor provides this automatically. For each address, you will have a column showing which file it was found in.
Store this provenance information alongside your contact lists. If a consumer submits a request to know, you can identify the source of their address.
Maintain a suppression list
A suppression list is a record of email addresses that must not be contacted. It serves two CCPA-related purposes:
- When a consumer requests deletion, their address goes on the suppression list so future extractions do not re-add it to active lists.
- When a consumer opts out, their address goes on the suppression list to prevent future contact.
Check every newly extracted list against your suppression list before using it. See What is an email suppression list.
Update your privacy policy
Your privacy policy should disclose:
- That you collect email addresses.
- The sources of those email addresses (for example, business documents, public records, conference materials).
- The purposes for which you use them.
- The categories of third parties you share them with, if any.
- The rights California residents have under the CCPA and how to exercise them.
Respond to requests within the deadline
The CCPA requires businesses to respond to consumer requests within 45 days, with the option to extend by an additional 45 days if necessary (with notice to the consumer). Have a process in place to handle requests before they arrive.
Verify the requester's identity
Before fulfilling a request to know, delete or correct, you must verify that the person making the request is the consumer whose information is involved. The verification process should be reasonable and proportionate to the sensitivity of the information.
CCPA vs. GDPR
If you also handle data from European residents, you may already be familiar with the GDPR. The two laws share some concepts but differ in important ways:
Scope. The GDPR applies to any organisation that processes personal data of people in the EU or EEA, regardless of the organisation's size or location. The CCPA applies only to for-profit businesses that meet specific revenue or data-volume thresholds and that handle California residents' data.
Legal basis. The GDPR requires a specific legal basis for processing (such as consent or legitimate interest). The CCPA does not require prior consent for most processing but gives consumers the right to opt out of certain uses.
Consent model. The GDPR generally follows an opt-in model for marketing. The CCPA follows an opt-out model for the sale or sharing of personal information.
Penalties. The GDPR allows fines up to 4 percent of global annual revenue. The CCPA allows fines of up to $2,500 per unintentional violation and $7,500 per intentional violation, enforced by the California Attorney General and the California Privacy Protection Agency.
If you are subject to both laws, the GDPR's requirements are generally stricter. Complying with the GDPR typically puts you in a strong position for CCPA compliance, but not necessarily the reverse.
What Email Extractor Does and Does Not Do
Email Extractor extracts email addresses from files in your browser. It does not:
- Track which addresses belong to California residents.
- Check addresses against a suppression list.
- Manage consent or opt-out status.
- Store addresses beyond the current browser session (though history can store result lists locally).
CCPA compliance is your responsibility as the business collecting and using the data. Email Extractor is one step in that process: extracting addresses from source files. The compliance steps around those addresses, including maintaining a suppression list, responding to consumer requests and updating your privacy policy, are separate tasks that you manage outside the tool.